A Sept. 1, 2026 multinational operation disrupted the Sality botnet, cutting off its operator's ability to deliver new malicious payloads to infected computers. However, malware already installed on those devices remains active and operational, according to CrowdStrike's report.
The operation affected more than 33,000 infected machines worldwide. U.S. authorities seized Sality-linked domains, while partners in Bulgaria, Hungary, and Romania acted against additional domains.
How the Threat Persists
CrowdStrike identified EggJagger as Sality's primary payload over the preceding eight years. The tool monitors the clipboard for cryptocurrency addresses and substitutes them with destinations controlled by the malware operator, affecting both Bitcoin and Ethereum transactions.
The attack works by watching when users copy a cryptocurrency address for payment. The malware replaces it with an address controlled by the operator. Users intending to pay the correct recipient may paste the substituted address into payment forms instead, inadvertently sending funds to the attacker's destination.
Because address-swapping software operates locally on infected computers, it can continue functioning after the botnet's communication channels are disrupted. Users with confirmed infections still need to remove the malware from their devices.
Technical Details
CrowdStrike describes Sality as a file infector that attaches to executable files and spreads through network shares, removable drives, and file sharing systems. The disruption changed the peer lists that infected machines use to communicate, isolating them from the operator and inserting defender-controlled servers.
CrowdStrike recommends network operators check logs and device telemetry for UDP traffic to the lighthouse address 188.166.101[.]148 as an indicator of Sality infection. The company provides YARA detection rules for scanning running processes.
The Shadowserver Foundation is working with internet service providers and incident response teams to identify infections and support user remediation.


